Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 24 Apr 2003 12:11:03 +0200
From:      Pawel Jakub Dawidek <nick@garage.freebsd.pl>
To:        Peter <pfak@telus.net>
Cc:        freebsd-hackers@freebsd.org
Subject:   Re: Keeping a large shellbox stable and secure
Message-ID:  <20030424101103.GV20444@garage.freebsd.pl>
In-Reply-To: <001901c309ee$36029070$c601a8c0@oxygen>
References:  <001901c309ee$36029070$c601a8c0@oxygen>

next in thread | previous in thread | raw e-mail | index | archive | help

--YttKMwf6abDJOSyE
Content-Type: text/plain; charset=iso-8859-2
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Wed, Apr 23, 2003 at 04:15:20PM -0700, Peter wrote:
+> Would ipfw2 or Ipfilter be better? Should I run RELENG_4 or RELENG_4_8.

I suggest RELENG_4_8 of course.

+> Any ideas would be appreciated. Basically, I'm attempting to make this b=
ox
+> as stable and secure as possible. Anything would be appreciated.

If we are talking about security, take a look at CerbNG project:

	http://cerber.sourceforge.net

But there is no stable release yet.
You can find on this page also two different kernel modules:
rexec and lrexec. Those two are stable, but not so functional and
doesn't provide so high security level as CerbNG.

--=20
Pawel Jakub Dawidek                       pawel@dawidek.net
UNIX Systems Programmer/Administrator     http://garage.freebsd.pl
Am I Evil? Yes, I Am!                     http://cerber.sourceforge.net

--YttKMwf6abDJOSyE
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (FreeBSD)

iQCVAwUBPqe4Nz/PhmMH/Mf1AQETlwP8DDxiDZ03gFVet//auEui4WxAAdJdKEc/
jydV1LMgHu+mC39Nd6Rgsc2D6rkD80+Ks+fA9Ao+fQWvWSWtNFA1ohwM7KigYvdb
uR3r5MiwknyQHgBFkaI8F3sZA5e3n1Ya1mWCjsGEk5GQqxKaRpNQ2lJUAUIG0/EM
YRhnIfWIBpk=
=QyOb
-----END PGP SIGNATURE-----

--YttKMwf6abDJOSyE--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20030424101103.GV20444>